CVE-2004-0121
Microsoft Outlook 2002 - 'Mailto' Quoting Zone Bypass
Severity Score
7.5
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
2
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as arguments when calling OUTLOOK.EXE, which allows remote attackers to use script code in the Local Machine zone and execute arbitrary programs.
Micrososft Outlook 2002 no filtra suficientemente los parámetros de URLs mailto:, cuando se usan como argumentos al llamar a OUTLOOK.EXE, lo que permite a atacantes remotos usar código script en la zona de seguridad "Máquina Local" y ejecutar programas arbitrarios.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2004-02-03 CVE Reserved
- 2004-03-09 First Exploit
- 2004-04-15 CVE Published
- 2024-03-09 EPSS Updated
- 2024-08-08 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
CAPEC
References (11)
URL | Tag | Source |
---|---|---|
http://marc.info/?l=bugtraq&m=107893704602842&w=2 | Mailing List | |
http://www.ciac.org/ciac/bulletins/o-096.shtml | Broken Link | |
http://www.kb.cert.org/vuls/id/305206 | Mitigation | |
http://www.us-cert.gov/cas/techalerts/TA04-070A.html | Broken Link | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/15414 | Third Party Advisory | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/15429 | Third Party Advisory | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A843 | Broken Link |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/23796 | 2004-03-09 | |
http://www.securityfocus.com/bid/9827 | 2024-08-08 |
URL | Date | SRC |
---|---|---|
http://www.idefense.com/application/poi/display?id=79&type=vulnerabilities | 2024-02-13 | |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-009 | 2024-02-13 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microsoft Search vendor "Microsoft" | Office Search vendor "Microsoft" for product "Office" | xp Search vendor "Microsoft" for product "Office" and version "xp" | sp2 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Outlook Search vendor "Microsoft" for product "Outlook" | 2002 Search vendor "Microsoft" for product "Outlook" and version "2002" | sp2 |
Affected
|